2026 · High

High-severity vulnerabilities disclosed in 2026

High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.

4140 published vulnerabilities · page 37 of 42

  • CVE-2026-14763HIGH 7.3

    A SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the tour parameter in the administrative tour reservations page. An attacker can exploit this remotely without special privileges or user interaction, potentially compromising sensitive reservation and customer data stored in the application database.

  • CVE-2026-14764HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation system version 1.0, specifically in the event management administrative interface. An attacker can inject malicious SQL commands through the event details parameter to manipulate database queries without requiring authentication. This allows unauthorized access to, modification of, or deletion of sensitive data stored in the application database.

  • CVE-2026-14768HIGH 7.3

    A SQL injection vulnerability has been discovered in code-projects Real State Services version 1.0 affecting the /builderHome.php file. An attacker can inject malicious SQL commands through the 'loc' parameter without authentication, potentially reading, modifying, or deleting database records. Public exploit code is available, making this a practical threat that requires immediate patching.

  • CVE-2026-14769HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 affecting the /pay.php file. An unauthenticated attacker can inject malicious SQL code through the Bankname parameter to manipulate database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is remotely exploitable without any user interaction, and proof-of-concept code has been publicly disclosed, increasing immediate risk.

  • CVE-2026-14770HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 that allows unauthenticated remote attackers to manipulate the ID parameter in the /edit_room.php file to execute arbitrary database queries. The vulnerability requires no user interaction and can be exploited from the network without authentication, making it a significant remote code execution risk for organizations running this scheduling software.

  • CVE-2026-14771HIGH 7.3

    SourceCodester's Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_exam1.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, allowing them to read, modify, or delete database contents without authentication. Because this vulnerability requires no user interaction and can be exploited over the network, it represents a significant risk to organizations running this application.

  • CVE-2026-14772HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 affecting the /edit_course1.php file. An attacker can manipulate the ID parameter to inject arbitrary SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires no authentication and can be exploited over the network. Public disclosure has occurred, increasing exploitation risk.

  • CVE-2026-14778HIGH 7.3

    A vulnerability exists in SourceCodester Online Examination & Learning Management System version 1.0 that allows attackers to bypass authorization controls in the enrollment management function. By manipulating enrollment-related parameters (student_id, schedule_id, and action) sent to the /ajax_enroll.php endpoint, an unauthenticated attacker can gain unauthorized access to enrollment data and functionality. The vulnerability can be exploited remotely without user interaction, and proof-of-concept details have been publicly disclosed.

  • CVE-2026-14802HIGH 7.3

    A command injection vulnerability exists in create-react-app's browser launching mechanism on macOS. An attacker can manipulate input to the startBrowserProcess function in openBrowser.js, causing arbitrary operating system commands to execute with the privileges of the developer running the build tool. This affects create-react-app versions up to 5.0.1. The vulnerability is remotely exploitable and does not require user authentication or interaction, making it a serious risk for development environments.

  • CVE-2026-15134HIGH 7.3

    CodeAstro Simple Online Leave Management System version 1.0 contains a SQL injection vulnerability in its index.php file. An attacker can manipulate the email parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data without authentication. The vulnerability is network-accessible and exploit code has already been made public, increasing the risk of active exploitation.

  • CVE-2026-15135HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Food Order System version 1.0, specifically in the /edit_food_items.php file. An attacker can manipulate the 'update' parameter to inject arbitrary SQL commands without authentication. This allows remote code execution and data manipulation. Public exploits are available, increasing immediate risk.

  • CVE-2026-15137HIGH 7.3

    A SQL injection vulnerability has been discovered in code-projects Interview Management System version 1.0. An attacker can manipulate the ID parameter in the application to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive data in the backend database. The vulnerability requires no authentication and can be triggered from the network without user interaction. Public exploit code is available, elevating the risk of active exploitation.

  • CVE-2026-15190HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. An attacker can manipulate the Username parameter in the login page (/login.php) to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data without authentication. The vulnerability is network-accessible and requires no user interaction, making it straightforward to exploit. Public exploit code is now available.

  • CVE-2026-15319HIGH 7.3

    Sipeed PicoClaw, a hardware tool used for embedded device programming and debugging, contains a flaw in how it controls who can access its web interface. The vulnerability allows attackers to bypass IP-based access restrictions through manipulation of the IPAllowlist function in the launcher component. An attacker on the network can exploit this to gain unauthorized access to the tool's backend without providing credentials. The flaw affects versions up to 0.2.9, and a patch (identified as 3126) is available.

  • CVE-2026-15330HIGH 7.3

    CowAgent, a tool used for AI agent functionality, contains a server-side request forgery (SSRF) vulnerability in its Vision Tool component. An attacker can manipulate image parameters passed to the vision processing function to force the server to make arbitrary requests to internal or external systems. This can be exploited remotely without authentication, potentially allowing attackers to access internal resources, interact with backend services, or exfiltrate sensitive data. The vulnerability affects versions up to 2.1.1 and is fixed in version 2.1.2.

  • CVE-2026-22078HIGH 7.3

    CVE-2026-22078 is a privilege escalation vulnerability in O+ Connect's inter-process communication (IPC) service. The service fails to verify the identity of applications attempting to communicate with it, allowing any authenticated user on the system to escalate their privileges and perform sensitive operations they shouldn't be able to access. This is a local attack that requires user interaction, but once exploited, can affect system stability and confidentiality.

  • CVE-2026-24180HIGH 7.3

    NVIDIA DALI contains a heap-based buffer overflow vulnerability that allows a local attacker with limited privileges to cause memory corruption. An attacker with user-level access could exploit this by supplying crafted input—potentially through user interaction—to overflow a heap buffer and execute arbitrary code, modify data, crash the application, or leak sensitive information. This is a local-only attack that requires an existing foothold on the system.

  • CVE-2026-24181HIGH 7.3

    NVIDIA DALI, a data loading library commonly used in machine learning pipelines, contains a flaw in index validation that could allow a local attacker with user-level privileges to execute arbitrary code, modify data, crash the application, or steal sensitive information. The vulnerability requires user interaction and operates within a single user's security context, but the potential consequences span the full spectrum of system compromise.

  • CVE-2026-30649HIGH 7.3

    A buffer overflow vulnerability exists in VIVOTEK's FD8136 network camera that allows an unauthenticated remote attacker to execute arbitrary code. The flaw is located in the set_getparam.cgi component, which handles parameter processing without proper boundary checks. An attacker on the network can send a specially crafted request to trigger the overflow and gain complete control of the device.

  • CVE-2026-30760HIGH 7.3

    SourceBans Material Admin, a web-based administration panel, contains a vulnerability that allows unauthenticated attackers to alter user data through a specially crafted XAJAX request. An attacker can send a malicious web request to manipulate account information, permissions, or other critical user attributes without needing valid credentials. This affects versions prior to 1.1.6.

  • CVE-2026-30761HIGH 7.3

    SourceBans Material Admin v1.1.6 contains a critical weakness in its image upload functionality that allows unauthenticated attackers to upload malicious files and execute arbitrary code on affected servers. An attacker can craft a specially designed image file that bypasses upload validation, leading to remote code execution without needing valid credentials or user interaction. This is a direct pathway to full system compromise.

  • CVE-2026-35314HIGH 7.3

    A flaw in Oracle Access Manager's web server plugin allows attackers on the network to bypass authentication and access the system without credentials. An unauthenticated attacker can read sensitive data, modify or delete information, and disrupt service availability. The vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. Because no prior authentication or user interaction is required, this is a relatively straightforward issue to exploit for anyone with network access.

  • CVE-2026-36609HIGH 7.3

    A vulnerability in Mercusys AC12G (EU) V1 routers with firmware version AC12G(EU)_V1_200909 allows attackers on the network to recover administrator passwords. The router uses a static authentication nonce (a security token) that remains the same for requests from the same IP address, and combines this with weak password encoding. An attacker who captures authentication traffic can reverse-engineer the encoding to extract plaintext credentials, potentially gaining full administrative control of the router.

  • CVE-2026-36611HIGH 7.3

    A Mercusys AC12G (EU) V1 router with firmware version AC12G(EU)_V1_200909 has a vulnerability that exposes uninitialized memory to attackers on the same network. When the router receives certain requests on its UPnP port without proper headers, it returns 128 bytes of raw memory content that should have been inaccessible. An attacker with network access can exploit this to leak sensitive internal data without needing credentials.

  • CVE-2026-37579HIGH 7.3

    SMSGate sms-core versions 2.1.13.6 and earlier contain a remote code execution vulnerability in the CMPP7 message handling component. An unauthenticated attacker on the network can exploit this flaw to execute arbitrary code on affected systems without any user interaction, potentially gaining full control of the SMS gateway infrastructure.

  • CVE-2026-39292HIGH 7.3

    Falco Solutions PHPPageBuilder version 0.31.0 has a file upload vulnerability that lets attackers upload malicious files without proper checks. An attacker can exploit this to upload executable code and run commands on the affected server, potentially taking complete control of the web application.

  • CVE-2026-40768HIGH 7.3

    CVE-2026-40768 is a HIGH-severity vulnerability in Salon booking systems version 10.30.24 and earlier that allows unauthenticated attackers to access, modify, or delete other users' booking records and sensitive information through Insecure Direct Object References (IDOR). An attacker can directly manipulate request parameters to reference booking IDs, customer profiles, or payment details belonging to other customers without needing valid credentials, potentially exposing or altering business operations and customer data.

  • CVE-2026-40993HIGH 7.3

    Spring Security versions 7.0.0 through 7.0.5 contain a deserialization vulnerability in how they manage SAML metadata. An attacker who has write access to specific database tables can insert malicious serialized code into credential storage columns. When the application deserializes this data, it executes the attacker's payload. This requires existing database write privileges, but the impact can be severe—potentially allowing unauthorized access or system manipulation.

  • CVE-2026-41046HIGH 7.3

    qSnapper before version 1.3.3 contains a path traversal vulnerability in how it handles the 'configName' parameter. A local attacker can exploit this to supply malicious configuration files to the snapper tool, leading to denial of service or potential privilege escalation to root. This is a local-only attack that requires no authentication and no user interaction.

  • CVE-2026-41121HIGH 7.3

    Dell Device Management Agent versions before 26.05 contain a link-following vulnerability that allows a low-privileged local attacker to escalate their privileges on an affected system. An attacker with basic user access could exploit a flaw in how the agent resolves file links to gain elevated permissions, potentially taking full control of the system.

  • CVE-2026-42061HIGH 7.3

    Acronis DeviceLock DLP on Windows contains a local privilege escalation vulnerability stemming from improper permission assignment to child processes. An authenticated user with limited privileges can exploit this flaw to gain elevated system access, potentially compromising data loss prevention controls and system integrity. The vulnerability requires local access and user interaction but delivers high-impact consequences including confidentiality, integrity, and availability breaches.

  • CVE-2026-42675HIGH 7.3

    Themefic Hydra Booking versions up to 1.1.41 contain a missing authorization flaw that allows attackers to bypass access controls and perform unauthorized actions. An attacker without authentication can exploit incorrectly configured security levels to access or modify booking data and functionality that should be restricted. This is a network-based vulnerability requiring no user interaction or special privileges.

  • CVE-2026-43825HIGH 7.3

    Apache OpenNLP's SvmDoccatModel contains a dangerous deserialization flaw that can allow attackers to execute arbitrary code. The vulnerability exists in how the library reads serialized model files—it deserializes untrusted data without proper validation, meaning malicious input can trigger code execution if certain common Java libraries are present on the system. This affects OpenNLP 3.x versions prior to 3.0.0-M4. The risk is highest for applications that load SvmDoccatModel instances from external or user-supplied sources.

  • CVE-2026-43866HIGH 7.3

    Apache Camel and its JMS-related components contain a critical deserialization bypass vulnerability that allows an attacker to inject malicious Exchange state into JMS applications. The issue stems from an incomplete fix to a prior vulnerability (CVE-2026-40860): while that patch added a class allowlist to prevent arbitrary object deserialization, it inadvertently allowed a Camel internal class (DefaultExchangeHolder) to slip through. An attacker who can publish a crafted ObjectMessage to a JMS queue or topic consumed by a vulnerable Camel application can exploit this to manipulate routing logic, inject headers, modify properties, and alter error handling—all without needing a complex deserialization gadget chain. The attack leverages only standard Java classes that all systems trust.

  • CVE-2026-44185HIGH 7.3

    Apache HTTP Server contains a buffer over-read vulnerability triggered when the server makes outbound OCSP (Online Certificate Status Protocol) requests to an attacker-controlled server. An attacker can craft a malicious OCSP response that causes the HTTP Server to read beyond allocated memory boundaries, potentially exposing sensitive data or causing service disruption. All versions from 2.4.0 through 2.4.67 are affected; upgrading to version 2.4.68 resolves the issue.

  • CVE-2026-44186HIGH 7.3

    Apache HTTP Server versions 2.4.0 through 2.4.67 contain a vulnerability in the mod_proxy_ftp module that can be triggered when the server proxies requests to a backend FTP server under attacker control. The vulnerability manifests as an infinite loop—a condition where the module becomes stuck in a repeating sequence and never exits cleanly. This can cause the affected worker process to hang indefinitely, consuming CPU resources and becoming unresponsive. An attacker does not need credentials or user interaction to exploit this; they only need to control or compromise the FTP server that the Apache proxy is configured to forward requests to.

  • CVE-2026-44609HIGH 7.3

    Acronis DeviceLock DLP for Windows contains a local privilege escalation flaw rooted in insecure executable (EXE) hijacking. An attacker with local system access and user-level privileges can exploit this vulnerability by substituting a legitimate executable that the application loads, forcing the system to run malicious code with elevated permissions. This is a user-interaction scenario—the victim must perform an action that triggers the vulnerable code path—but once activated, it grants an attacker full system control over the affected machine.

  • CVE-2026-44682HIGH 7.3

    Acronis DeviceLock DLP for Windows contains a vulnerability that allows a local user to gain elevated system privileges through DLL hijacking. An attacker with basic user-level access can exploit this flaw to escalate to administrator or system privileges, potentially compromising the entire endpoint. The vulnerability requires the user to interact with the application, such as launching a dialog or feature that triggers the malicious DLL load.

  • CVE-2026-45011HIGH 7.3

    ApostropheCMS version 4.29.0 contains a stored cross-site scripting (XSS) flaw in its image widget feature. An Editor-level user can inject malicious JavaScript code into an image link, and because editors can publish content directly to the live site, that payload executes whenever anyone—including administrators or public visitors—interacts with the affected widget. This is a persistent attack: the malicious code remains on the published page until removed, affecting all subsequent visitors.

  • CVE-2026-45360HIGH 7.3

    Apache Airflow's scheduler contains a deserialization vulnerability in how it handles deadline references created by DAG authors. When a DAG author creates a custom deadline reference, the scheduler deserializes it without validating what code it might execute. An attacker who can author a DAG—or influence its contents—can embed malicious class paths that the scheduler will import and instantiate, gaining the ability to execute arbitrary code within the scheduler's security context and access its database connection.

  • CVE-2026-45364HIGH 7.3

    Better Auth, a TypeScript authentication library, contained a rate-limiting bypass that allowed attackers to circumvent protections on sensitive endpoints like sign-in, sign-up, and password reset. The vulnerability exploited how the library handled IPv6 addresses in rate-limiting checks. IPv6 clients could generate an enormous number of distinct request origins (up to 2^64 per /64 subnet) by rotating through different source addresses, or bypass limits by varying how a single IPv6 address was encoded (uppercase vs. lowercase, compressed vs. full format, IPv4-mapped notation). This rendered rate limiting ineffective against brute-force attacks on authentication endpoints. Fixed in versions 1.4.17 and 1.5.0-beta.9.

  • CVE-2026-45481HIGH 7.3

    A cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint allows an authenticated user to inject malicious scripts into web pages. An attacker with valid SharePoint access can craft a specially formed input that bypasses input validation, causing the server to generate pages containing attacker-controlled JavaScript. When other authorized users view the compromised page, their browser executes the injected script in the context of the SharePoint application, enabling the attacker to impersonate them, steal session tokens, or perform actions on their behalf. The vulnerability requires user interaction (clicking a link or visiting a page) but poses significant risk within organizations that rely on SharePoint for document management and collaboration.

  • CVE-2026-46250HIGH 7.3

    CVE-2026-46250 is a critical initialization failure in the Linux kernel affecting MIPS-based systems. The vulnerability arises from a compiler bug in LLVM versions 18–21 where the compiler incorrectly restores the `$gp` (global pointer) register even when code intentionally modifies it as a global register variable. On MIPS, the kernel uses `$gp` to track the current thread info, and during boot the kernel relocates itself and updates `$gp` accordingly. When LLVM restores the old `$gp` value after this intentional modification, the register points to pre-relocation memory, causing the kernel to crash during the `init_idle` phase of scheduler initialization. This affects MIPS-based systems including Loongson and other MIPS processors, particularly those compiled with affected LLVM versions.

  • CVE-2026-46328HIGH 7.3

    A vulnerability exists in the Linux kernel's AppArmor security module where resource limits (rlimits) for POSIX CPU timers are not being properly enforced. AppArmor is designed to restrict what processes can do, but this flaw means the CPU timer limits may not be correctly applied when a process is confined by AppArmor policies. An attacker with local access could exploit this to exceed intended resource restrictions, potentially causing performance degradation or denial of service on the affected system.

  • CVE-2026-46587HIGH 7.3

    Apache Camel contains an input validation flaw that allows attackers to send specially crafted requests to affected systems without authentication. The vulnerability can lead to information disclosure, unauthorized modifications, and service disruption. Organizations running vulnerable versions of Camel should prioritize upgrading to patched releases.

  • CVE-2026-46588HIGH 7.3

    Apache Camel, a widely-used open-source integration framework, contains a flaw in how it validates user input. This weakness allows an attacker to send specially crafted requests over the network without authentication, potentially compromising the confidentiality, integrity, or availability of affected systems. The vulnerability spans multiple version lines, affecting releases through 4.14.7, versions 4.15.0 through 4.18.2, and versions 4.19.0 through 4.20.0.

  • CVE-2026-46734HIGH 7.3

    Dell Display and Peripheral Manager (DDPM) for Mac versions before 2.3 fail to properly validate SSL/TLS certificates, allowing an attacker with local access and low-level user privileges to intercept or spoof secure connections. By presenting a forged or expired certificate, an attacker could bypass the software's security protections and potentially steal sensitive data or modify device settings without detection.

  • CVE-2026-47634HIGH 7.3

    A vulnerability in Microsoft Office SharePoint allows someone with valid access to inject malicious content that tricks downstream components into displaying fake or spoofed information to other users. The attacker must have legitimate credentials and convince a user to interact with the malicious content, but once triggered, the attack succeeds reliably and can achieve high impact by either stealing sensitive data or modifying what users see.

  • CVE-2026-48546HIGH 7.3

    KanaDojo, a Node.js application, contains a critical vulnerability in its automated pull request response workflow that allows attackers to escape the intended sandbox isolation and run arbitrary code on GitHub Actions runners. An attacker who can submit a pull request can craft a malicious modification to trigger code execution with the privileges of the automation token, potentially compromising the repository and downstream systems.

  • CVE-2026-48547HIGH 7.3

    KanaDojo has a command injection vulnerability in its GitHub Actions release workflow. An attacker with pull request access can embed shell commands into specific fields of a configuration file (patchNotesData.json), which get executed without sanitization when the workflow runs. This allows arbitrary command execution on the GitHub Actions runner, which has write permissions to the repository and access to secrets. The attack requires the malicious pull request to be merged, making it a supply-chain risk for projects using this tool.

  • CVE-2026-48913HIGH 7.3

    Apache HTTP Server's HTTP/2 module (mod_http2) contains a use-after-free vulnerability that can be triggered when the system runs out of available file handles. An unauthenticated attacker on the network can exploit this flaw to cause memory corruption, potentially leading to information disclosure, data modification, or service disruption. The vulnerability affects versions 2.4.55 through 2.4.67 of Apache HTTP Server.

  • CVE-2026-49042HIGH 7.3

    Apache Camel, a widely used integration framework, contains an improper input validation vulnerability that allows unauthenticated attackers to send malformed requests over the network. This flaw can lead to information disclosure, data manipulation, or service disruption depending on how the affected application processes untrusted input. The vulnerability affects multiple version lines and requires immediate patching to maintain security posture.

  • CVE-2026-49401HIGH 7.3

    Deno's permission system on macOS can be bypassed using Unicode character variations that represent the same filename. When you tell Deno to block access to a file using `--deny-read`, `--deny-write`, `--deny-run`, or `--deny-ffi`, the runtime compares the requested path against your deny rule at the byte level. However, APFS (Apple's filesystem) treats different Unicode representations of the same character as identical files. An attacker can exploit this mismatch by requesting a file using an alternate Unicode spelling, circumventing the intended permission restriction. This is fixed in Deno 2.7.14.

  • CVE-2026-49942HIGH 7.3

    Net::CIDR::Set, a Perl library for managing CIDR network blocks, contains a validation flaw in versions through 0.20 that allows attackers to bypass network access controls. The vulnerability stems from improper handling of network masks—the library accepts Unicode digit characters (such as Arabic-Indic numerals) and non-digit characters in mask fields, treating them as valid input. Additionally, leading zeros in masks are processed as decimal rather than octal, creating confusion about which networks are actually permitted. Together, these issues can cause the library to accept significantly larger or differently scoped networks than intended, potentially allowing unauthorized traffic or connections that should have been blocked.

  • CVE-2026-50015HIGH 7.3

    pnpm, a popular package manager, has a path traversal vulnerability in its patch application system that allows malicious actors to write or delete files outside the intended package directory. An attacker can exploit this by submitting a pull request with a specially crafted .patch file containing directory traversal sequences (../../). When another developer runs pnpm install, the malicious patch executes with their privileges, potentially compromising the system. The vulnerability affects versions prior to 10.34.0 and 11.4.0, where it has been patched.

  • CVE-2026-50033HIGH 7.3

    Acronis DeviceLock DLP for Windows contains a local privilege escalation flaw caused by insecure DLL loading. An authenticated user with limited privileges can trick the application into loading a malicious DLL from an attacker-controlled location, gaining elevated system rights. The vulnerability requires local access and user interaction, but can result in complete system compromise.

  • CVE-2026-50132HIGH 7.3

    Budibase prior to version 3.39.0 contains a critical account-linking flaw in its public chat integration endpoint. An attacker can craft a malicious link that, when clicked by an authenticated Budibase user, silently binds that user's account to the attacker's Slack, Discord, or Microsoft Teams identity—without the user's knowledge or consent. This gives the attacker the ability to impersonate the victim within chat-integrated workflows and potentially access sensitive data or perform actions on their behalf. The vulnerability requires no special privileges to exploit and succeeds through simple social engineering (tricking a user into clicking a link).

  • CVE-2026-50593HIGH 7.3

    Graphite, a font rendering engine, contains a flaw where it fails to properly validate memory boundaries when processing certain font actions. An attacker can craft a malicious font file that, when opened by a user, triggers an integer underflow—a type of math error that causes the program to write data outside the intended memory area. This out-of-bounds write can corrupt memory, crash the application, or potentially execute arbitrary code. The vulnerability requires user interaction (opening the font) and affects local users on the system.

  • CVE-2026-53404HIGH 7.3

    Apache Tomcat's URL rewrite valve contains a logic flaw where the processing of conditional rules breaks when an OR condition is matched first. Instead of continuing to evaluate remaining conditions as designed, the system incorrectly skips over non-OR conditions that should still be checked. This can cause rewrite rules to behave unpredictably, potentially allowing traffic that should be blocked or modifying requests in unintended ways. The flaw affects multiple Tomcat versions across several release branches.

  • CVE-2026-53473HIGH 7.3

    A cross-site scripting (XSS) vulnerability exists in Red Hat's migration-planner-ui-app that allows an attacker to inject malicious JavaScript code through a specially crafted discovery agent registration. When a legitimate user clicks a malicious link in the application interface, the JavaScript executes in their browser within their authenticated session. An attacker can exploit this to hijack the user's Red Hat Single Sign-On credentials and potentially access data and perform actions across multiple tenants within the affected environment.

  • CVE-2026-53963HIGH 7.3

    A flaw in Discourse allows an attacker with an account on the platform to inject malicious code into a second factor (like a 2FA security key) display name. When a site administrator impersonates that attacker's account for troubleshooting or support purposes, the unescaped name executes in the admin's browser, potentially letting the attacker steal the admin's session, modify forum content, or perform other harmful actions. The issue stems from insufficient sanitization in the account deletion confirmation dialog.

  • CVE-2026-54263HIGH 7.3

    Wagtail, a Django-based open-source content management system, contains a reflected cross-site scripting (XSS) flaw in its admin interface's dynamic image URL generator. A lower-privileged admin editor can craft a malicious URL that, when clicked by a higher-privileged admin user, executes actions under that user's account. This affects all Wagtail installations, though only admin users are at risk—ordinary site visitors cannot exploit it. The issue has been patched in versions 7.0.8, 7.3.3, and 7.4.2.

  • CVE-2026-54328HIGH 7.3

    Pi, a lightweight terminal-based coding environment, contains a privilege escalation vulnerability in versions 0.74.0 through 0.78.0. When Pi installs temporary npm or git extension packages, it uses predictable file paths in the system's shared temporary directory. On multi-user Linux systems, an attacker with local access could place malicious code at these predictable locations before a victim user runs Pi, causing the victim's session to load and execute the attacker's code. This is a local attack requiring both system access and user interaction, but successful exploitation grants the attacker full code execution within the victim's process.

  • CVE-2026-54479HIGH 7.3

    CVE-2026-54479 is a session management flaw in a WebSocket-based backend system used for charging station operations. The vulnerability stems from the use of predictable and reusable session identifiers that fail to enforce uniqueness across multiple concurrent connections. An attacker can exploit this to impersonate legitimate users or launch denial-of-service attacks by flooding the backend with requests using valid (but guessable) session tokens. The flaw requires no authentication or user interaction to exploit and can be triggered from any network location.

  • CVE-2026-55501HIGH 7.3

    9Router versions before 0.4.80 contain a login rate-limiting bypass vulnerability in their AI router dashboard. The authentication system incorrectly trusts the X-Forwarded-For HTTP header—a value that any attacker can spoof—to identify users for rate-limit enforcement. By rotating this header on each login attempt, an attacker can bypass the 5-attempt lockout threshold and perform unlimited password guesses against the dashboard without triggering progressive lockout delays. This puts any 9Router deployment with a publicly accessible dashboard at risk of credential compromise.

  • CVE-2026-55957HIGH 7.3

    Apache Tomcat contains an authentication bypass vulnerability when GSSAPI-based LDAP authentication is enabled through JNDIRealm. An attacker can log in without providing a valid password, gaining unauthorized access to the application. The flaw affects multiple Tomcat versions spanning nearly two decades of releases, from version 7 through 11.

  • CVE-2026-56790HIGH 7.3

    CANBoat, a popular NMEA-2000 marine data parser, contains a critical boundary-checking flaw that crashes the application when it encounters a malformed message. An attacker with access to a vessel's CAN bus network—or someone sending crafted data over an IP-based N2K connection—can trigger this crash by sending a message with an invalid parameter code. The vulnerability affects all versions through 6.22 and is resolved in a patched commit available from the maintainers.

  • CVE-2026-57028HIGH 7.3

    Juniper Networks Junos OS Evolved contains a flaw that exposes an internal license management process to the network. An attacker without credentials can reach this normally internal-only function over the internet and trigger license exhaustion, effectively denying service to legitimate users. The vulnerability stems from improper initialization of network communication boundaries.

  • CVE-2026-57915HIGH 7.3

    Apache Kerby, an open-source implementation of the Kerberos protocol, contains a flaw in its pre-authentication validation logic. An attacker can craft a malicious authentication request containing a PA-DATA field with an unrecognized or unsupported type, allowing them to bypass the pre-authentication checks that normally prevent unauthorized access. This effectively weakens the initial security gate that protects against brute-force and replay attacks in Kerberos authentication flows.

  • CVE-2026-58014HIGH 7.3

    A bug in GLib's key file parsing function can cause the application to read one byte beyond allocated memory when processing key files with empty values. This memory access violation may leak sensitive information, corrupt data, or crash the application. The vulnerability requires no user interaction and can be exploited over the network against systems that use the affected GLib versions to parse untrusted configuration or data files.

  • CVE-2026-58379HIGH 7.3

    GIMP contains a memory corruption flaw in how it processes Paint Shop Pro (PSP) image files. When a user opens a specially crafted PSP file with low bit-depth image data, the application miscalculates how much memory to allocate, causing it to write data past the intended buffer boundary. An attacker can exploit this by distributing a malicious PSP file; if opened, it could allow the attacker to run arbitrary code on the victim's system or crash the application. The vulnerability requires user interaction—someone must be tricked into opening the file—but once that happens, the attacker gains significant control.

  • CVE-2026-58380HIGH 7.3

    GIMP, the popular open-source image editor, contains a memory corruption vulnerability in how it reads PNM image files. When a user opens a malicious PNM file, a coding mistake causes the application to write data slightly outside a memory buffer's intended boundary, which can crash the program or potentially allow an attacker to execute arbitrary code on the system. The flaw requires local access and user interaction (opening a file), but once triggered, the impact is substantial.

  • CVE-2026-58384HIGH 7.3

    GIMP, the widely-used open-source image editor, contains a vulnerability in how it parses Photoshop (PSD) files. When opening a specially crafted PSD file, GIMP miscalculates memory requirements during decompression, leading to insufficient memory being allocated. Attackers can then write data into areas they shouldn't, corrupting the program's memory. This could crash GIMP or potentially allow code execution if an attacker carefully crafts the malicious file.

  • CVE-2026-59214HIGH 7.3

    Open WebUI versions before 0.10.0 contain a vulnerability that allows stored malicious chat payloads to execute with the privilege level of the logged-in user. When a victim clicks a 'Run' button on a chat message, embedded code can make authenticated requests to the server—including administrative endpoints—and potentially execute arbitrary server-side code through the platform's tool configuration system. This is a stored attack, meaning the payload persists until the victim interacts with it.

  • CVE-2026-59794HIGH 7.3

    JetBrains TeamCity contains a stored cross-site scripting (XSS) vulnerability on the cloud profile page. An authenticated attacker can inject malicious scripts through agent-reported data that persist on the page and execute in the browser of any user viewing that profile, potentially stealing session tokens or performing actions on behalf of the victim. The vulnerability affects TeamCity versions before 2026.1.2 and requires an authenticated user with a valid login to exploit.

  • CVE-2026-6040HIGH 7.3

    CVE-2026-6040 is a memory safety vulnerability in ODF (Open Document Format) number format parsing. When a document contains a malformed number format with blank-width characters, a position value embedded in that format is not validated before being used to access the format-code string. This can cause the application to read from memory outside the intended buffer—a use-after-free condition. An attacker who crafts a malicious ODF document with a specially formed number format could trigger this flaw, potentially leading to information disclosure, data corruption, or application crash when the document is opened by a user.

  • CVE-2026-8079HIGH 7.3

    Progress Flowmon contains a privilege escalation vulnerability affecting versions before 12.5.9 and 13.0.11. An authenticated user with low-level permissions can manipulate requests during PDF generation to execute operations as a different user, potentially viewing restricted data or altering system settings they should not have access to. The vulnerability requires user interaction (someone must initiate or be tricked into initiating a PDF generation) but is otherwise straightforward to exploit once access is gained.

  • CVE-2026-8589HIGH 7.3

    GitLab Enterprise Edition contains a vulnerability that allows authenticated users with administrative privileges to inject unauthorized email addresses into other users' accounts. The flaw stems from insufficient input validation in group settings, where attacker-supplied data is not properly sanitized before being processed. This could enable account takeover, unauthorized access recovery through password resets, or privilege escalation if the injected email belongs to an attacker-controlled domain.

  • CVE-2026-8876HIGH 7.3

    Securly version 3.0.7 of their Chrome Extension contains hardcoded encryption keys embedded directly in the minified JavaScript file. These keys are meant to protect sensitive data like crisis alert keywords and intervention site configurations, but because they're hardcoded and visible in the browser extension code, anyone with access to the extension can decrypt that data. This is a classic case of storing secrets where they shouldn't be stored—effectively rendering the encryption useless.

  • CVE-2026-9029HIGH 7.3

    A vulnerability in Grafana allows users with Editor permissions to inject malicious scripts into map panel settings. When another user views the dashboard, that script runs in their browser, potentially compromising their session, stealing credentials, or performing actions on their behalf. This is a stored attack—the malicious code persists in the dashboard configuration.

  • CVE-2026-9080HIGH 7.3

    A use-after-free bug in libcurl allows attackers to crash applications or potentially execute code when specific callback functions are invoked during multi-socket operations. The vulnerability is triggered when `curl_easy_pause()` is called from within libcurl's event-based socket callback handler, causing the library to write to memory that has already been freed. This is a memory safety issue that affects applications using libcurl's multi interface with socket callbacks.

  • CVE-2026-9086HIGH 7.3

    Keycloak has a security flaw that allows administrators or users with client management permissions to register fake login applications with malicious redirect URIs. By crafting these URIs using case-insensitive JavaScript or data schemes, an attacker can inject and execute malicious code when administrators or users interact with logout flows or the admin console. The vulnerability requires the attacker to have elevated privileges within the system and the victim to click a crafted link, but successful exploitation could compromise the Keycloak server and any accounts or data it protects.

  • CVE-2026-9334HIGH 7.3

    CVE-2026-9334 is a type-confusion vulnerability in Cpanel::JSON::XS (a Perl JSON parsing library) that occurs when a specific feature called dupkeys_as_arrayref is enabled. When decoding JSON with duplicate object keys, the library crashes and attempts to dereference attacker-controlled data as a pointer. An attacker can exploit this by sending crafted JSON to any application using this library with the vulnerable setting enabled, potentially leading to denial of service or information disclosure.

  • CVE-2026-9658HIGH 7.3

    Plack::Middleware::Security::Common, a security middleware for Perl web applications, contains a flaw in how it filters HTTP header injection attacks when they appear in request paths. The middleware was designed to block header injections but only reliably caught attacks that were double-encoded. Single-encoded CRLF sequences (carriage return/line feed) embedded in request paths could slip through, potentially allowing attackers to inject malicious HTTP headers. The actual impact depends on how reverse proxies and the underlying Plack-based server process these malformed requests, which remains unclear in practice.

  • CVE-2026-9758HIGH 7.3

    A certificate validation flaw in S2OPC allows specially crafted untrusted certificates to be incorrectly accepted as trusted. An attacker can exploit this by presenting a well-formed but unauthorized certificate that the system mistakenly treats as legitimate, potentially enabling man-in-the-middle attacks or unauthorized access to protected communications.

  • CVE-2026-9795HIGH 7.3

    A flaw in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature allows a limited administrator to bypass security controls and inject high-privilege roles into a client application. When users authenticate to that client, the injected roles appear in their authentication tokens, granting them unauthorized access. An attacker with restricted admin rights can escalate their own permissions or those of other users without triggering standard approval workflows.

  • CVE-2016-20066HIGH 7.2

    WordPress CP Polls version 1.0.8 contains a persistent cross-site scripting (XSS) vulnerability in its file upload functionality. An attacker can upload a file containing malicious scripts with event handlers (such as onerror attributes) that will execute in the browsers of any user who views the uploaded content. This allows attackers to steal session cookies, redirect users to malicious sites, deface content, or perform actions on behalf of legitimate users without their knowledge.

  • CVE-2016-20084HIGH 7.2

    WordPress appointment-booking-calendar plugin version 1.1.24 contains a critical security flaw that allows attackers without any login credentials to inject malicious code into the plugin's settings. By crafting specially designed web requests, an attacker can plant persistent malicious scripts that execute whenever administrators access the calendar or view calendar settings. This creates a pathway for attackers to steal admin credentials, perform unauthorized actions, or compromise the entire WordPress installation.

  • CVE-2023-54351HIGH 7.2

    The Sonaar Music Plugin for WordPress version 4.7 contains a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious JavaScript code through the comment functionality on music playlist pages. When site visitors view these playlists, the malicious script executes in their browsers, potentially allowing attackers to steal session cookies, redirect users, deface content, or perform actions on behalf of the victim. No authentication is required to exploit this vulnerability.

  • CVE-2025-11262HIGH 7.2

    Link Whisper Free, a WordPress plugin, contains a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious scripts into web pages. When site visitors access affected pages, the injected scripts execute in their browsers, potentially allowing attackers to steal credentials, redirect users, or perform actions on their behalf. The vulnerability stems from improper handling of the user_id parameter and affects all versions up to 0.9.0.

  • CVE-2025-27511HIGH 7.2

    GeoServer, a widely-used open-source geospatial data platform, contains a vulnerability in its DB2 DataStore Extension that allows authenticated administrators to execute arbitrary code on the server through a malicious database connection string. An attacker with admin credentials can craft a specially crafted DB2 JDBC URL that exploits JNDI (Java Naming and Directory Interface) injection to achieve remote code execution. The vulnerability was patched in version 2.27.0.

  • CVE-2025-41265HIGH 7.2

    Waterfall Security's WF-500 TX Host contains a command injection flaw in its web-based administration interface. An attacker with valid administrative credentials can inject malicious operating system commands through the web UI, leading to arbitrary command execution on the device itself. This is a post-authentication attack—the attacker must already have admin-level access—but once inside, they can run any OS-level commands the host permits.

  • CVE-2025-41266HIGH 7.2

    A command injection vulnerability exists in the Waterfall WF-500 TX Host administration interface that allows authenticated users with elevated privileges to execute arbitrary system commands. An attacker who has already gained administrative access can leverage this flaw to run operating system-level commands, potentially compromising the entire appliance. The vulnerability affects version 7.9.1.0 R2502171040 and requires the attacker to be authenticated and have high-level privileges, reducing but not eliminating the risk in environments where admin credential exposure is a concern.

  • CVE-2025-41267HIGH 7.2

    A command injection vulnerability exists in the Waterfall WF-500 TX Host administration web interface that allows authenticated administrators to execute arbitrary operating system commands. An attacker with administrative credentials can craft malicious input through the WebUI to bypass command sanitization and gain direct OS-level access to the device. This is a post-authentication attack requiring valid admin credentials, but once exploited, provides complete system compromise.

  • CVE-2025-41279HIGH 7.2

    Nozomi Networks Labs discovered a command injection vulnerability in Waterfall's WF-500 RX Host administration interface. An authenticated attacker with administrative privileges can inject operating system commands through the web UI, leading to arbitrary code execution on the affected device. This is a serious risk for organizations using this industrial security appliance, as the attacker would gain full control of the host system.

  • CVE-2025-52465HIGH 7.2

    GeoServer, an open-source geospatial data server, contains a vulnerability that allows authenticated administrators to write the master password to arbitrary files on the server. An attacker with admin credentials can navigate to the Master Password Dump page and specify an absolute file path to dump the plaintext master password, potentially exposing it to unauthorized access or further compromise. This requires the attacker already have administrative access and the target file path must not exist, but the vulnerability significantly reduces the security of GeoServer's most sensitive credential.

  • CVE-2025-62850HIGH 7.2

    A NULL pointer dereference flaw in QNAP QuTS hero operating system can allow an administrator account holder to crash the storage system, causing service interruption. The vulnerability requires valid admin credentials to exploit, limiting its immediate exposure to insider threats or compromised admin accounts. QNAP has released patched versions across multiple QuTS hero branches.

  • CVE-2025-66273HIGH 7.2

    QNAP NAS systems running vulnerable versions of QTS and QuTS hero contain a command injection flaw that allows an authenticated administrator to execute arbitrary commands on the device. An attacker who obtains admin credentials—either through credential compromise, social engineering, or internal threat—can leverage this vulnerability to gain full control over the NAS, potentially accessing stored data, modifying configurations, or using the device as a pivot point into the network. The vulnerability requires valid administrative access, so it represents a privilege escalation or lateral movement risk rather than an unauthenticated remote attack.

  • CVE-2025-66279HIGH 7.2

    A command injection flaw in QNAP operating systems allows an authenticated administrator to run arbitrary commands on affected NAS devices. The vulnerability requires valid admin credentials, limiting exposure to insider threats or attackers who have compromised an admin account. QNAP has patched multiple OS versions including QTS 5.2.9.3410 build 20260214 and later, and several QuTS hero releases.

  • CVE-2025-66280HIGH 7.2

    QNAP has patched an integer overflow vulnerability affecting their NAS operating systems. The flaw requires an attacker to first obtain administrator credentials, then exploit the memory handling weakness to gain elevated control or crash the system. While the barrier to entry is high—needing valid admin access—the potential impact is severe because it affects core system integrity. QNAP has released patched versions across QTS and QuTS hero product lines.